Online Questions - Valid Practice To your 300-620 Exam (Updated 391 Questions)
Practice To 300-620 - Remarkable Practice On your Implementing Cisco Application Centric Infrastructure Exam
Exam Outline
The Cisco 300-620 exam equips the professionals with the skills required to install, configure, and maintain data center technology. The content of this test revolves around six domains that are listed below:
- ACI Packet Forwarding (15%)
- ACI Management (20%)
- External Network Connectedness (20%)
NEW QUESTION # 204
A network engineer configures the Cisco ACI fabric to connect to vCenter with these requirements:
Port groups must be automatically created on the distributed virtual switch.
Port groups must use the VLAN allocation in the range between 20-30.
The deployment must optimize the CAM space on the leaf switches.
Which set of actions meets these criteria?
- A. Create a dynamic VLAN pool with the VLAN range of 20-30.
Create a physical domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to On Demand. - B. Create a static VLAN pool with the VLAN range of 20-30.
Create a physical domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to Immediate. - C. Create a dynamic VLAN pool with the VLAN range of 20-30.
Create a VMM domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to On Demand. - D. Create a static VLAN pool with the VLAN range of 20-30.
Create a VMM domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to Immediate.
Answer: C
NEW QUESTION # 205
Which two objects are part of a Cisco ACI contract? (Choose two.)
- A. filter
- B. constraint
- C. subject
- D. policy
- E. version
Answer: A,C
Explanation:
A contract is composed of subjects, which define how communication occurs, and filters, which specify the permitted traffic within that contract.
NEW QUESTION # 206
Refer to the exhibit. The VMs called VM1 and VM2 are deployed on the ESXi Server in a Cisco ACI environment.
VM1 has MAC address A and an IP address 192.168.1.1/24, and VM2 has MAC address B.
VM1 has been shut down. Which set of actions must be taken to detect the movement of IP address 192.168.1.1/24 to MAC address B?
- A. Disable ARP flooding.
Enable unicast routing.
Disable GARP-based detection. - B. Enable ARP flooding.
Enable unicast routing.
Enable GARP-based detection. - C. Enable ARP flooding.
Disable unicast routing.
Enable GARP-based detection. - D. Disable ARP flooding.
Disable unicast routing.
Disable GARP-based detection.
Answer: B
Explanation:
GARP is used to update IP to MAC relation on upstream network devices. It is most relevant in case of vmotions or VMs/servers moving from one host to another, and the MAC address changes, but the IP remains the same.
In the context of ACI, the leaf switches can detect MAC and IP address movement between leaf switch ports, leaf switches, bridge domains, and EPGs, but it does not detect the movement of an IP address to a new MAC address if the new MAC address is from the same interface and same EPG as the old MAC address.
When the GARP based detection option is enabled (configuration available under the BD), Cisco ACI will trigger an endpoint move based on GARP packets if the move occurs on the same interface and same EPG. If a GARP packet comes from the same interface and same EPG, then endpoint learning is triggered only when Unicast Routing, ARP Flooding, and "GARP based detection" are all enabled for the bridge domain.
NEW QUESTION # 207
Refer to the exhibit.
Which two components should be configured as route reflectors in the ACI fabric? (Choose two.)
- A. Leaf1
- B. Spine2
- C. Leaf2
- D. apic1
- E. Spine1
- F. apic2
Answer: B,E
NEW QUESTION # 208
When creating a subnet within a bridge domain, which configuration option is used to specify the network visibility of the subnet?
- A. subnet control
- B. scope
- C. limit IP learning to subnet
- D. gateway IP
Answer: D
NEW QUESTION # 209
Which tenant is used when configuring in-band management IP addresses for Cisco APICs, leaf nodes, and spine nodes?
- A. infra
- B. mgmt
- C. common
- D. default
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/kb/ b_KB_Configuring_Static_Management_Access.html#concept_CFF63FEBE947424291B0F10E6F23DA7D
NEW QUESTION # 210
Refer to the exhibit. A Cisco ACI fabric connects with the same L3Out to SW1 and SW2. The fabric has a single tenant and single VRF. Which two actions must be taken to allow Host1 to communicate with the external EPG subnet? (Choose two.)
- A. Check the box of No Default SVI Gateway under Telco_BD.
- B. Add subnet 2a01:8c8:03a0:3::2/64 under Telco_EPG.
- C. Add subnet 2a01:8c8:03a0:3::2/64 under Telco_EPG.
- D. Associate bridge domain Telco_BD to L3out_Telco.
- E. Disable unicast routing on bridge domain Telco_BD.
Answer: B,D
Explanation:
The bridge-domain subnet that contains Host1 and its default gateway (2a01:8c8:03a0:3::1/64) must be configured as advertised externally so it is reachable via the L3Out.
The bridge domain Telco_BD must be associated with L3out_Telco so that routing between Host1's subnet and the external EPG subnet can occur.
NEW QUESTION # 211
The Application team reports that a previously existing port group has disappeared from vCenter.
An engineer confirms that the VM domain association for the EPG is no longer present.
Which action determines which user is responsible for the change?
- A. Check the EPG audit logs for the "deletion" action and compare the affected object and user.
- B. Examine the health score and drill down to an object that affects the EPG combined score.
- C. Inspect the server logs to see who was logging in to the APIC during the last few hours.
- D. Evaluate the potential faults that are raised for that EPG.
Answer: D
NEW QUESTION # 212
An engineer must connect a new host to port 1 »'1 on Leaf 101. A Cisco ACI fabric has an MOP policy configured but experience excessive Layer 2 loops The engineer wants the Cisco ACI fabric to detect and prevent Layer 2 loops m the fabric Which set of actions accomplishes these goals'?
- A. Option C
- B. Option A
- C. Option B
- D. Option D
Answer: C
Explanation:
To detect and prevent Layer 2 loops in a Cisco ACI fabric, the engineer must configure the Mis-Cabling Protocol (MCP) and related policies. MCP is designed to detect loops in Layer 2 network segments connected to ACI access ports and operates in conjunction with Spanning Tree Protocol (STP) running on external Layer 2 networks. The steps to accomplish these goals include:
Enable MCP Globally: Ensure that MCP is enabled globally on all access ports, virtual ports, and virtual port channels (VPCs) unless they are disabled at the individual port level1.
Configure MCP Transmit Frequency: Set the transmit frequency to a value that allows for quick loop detection. Starting with the 3.2(1) release, the Cisco ACI fabric provides faster loop detection with transmit frequencies from 100 milliseconds to 300 seconds1.
Set Action on Loop Detection: Decide how the MCP policies will act upon loop detection. Options include generating a syslog message or disabling the port upon detection of a loop1.
Implement Error Disabled Recovery Policy: Configure an error disabled recovery policy to automatically re-enable ports that were disabled due to loop detection after a configurable interval1.
By following these steps, the engineer can ensure that the Cisco ACI fabric will detect and prevent Layer 2 loops, thereby maintaining a stable and efficient network environment.
Reference:
Cisco APIC Online Help - Loop Detection1
ACI Layer 2 loop detection and Mitigation - Cisco Video Portal2
NEW QUESTION # 213
Refer to the exhibit.
An engineer is implementing a BPDU filter on external switch interfaces That face the Cisco ACI fabric to prevent excessive TCNs from impacting the fabric. Which Configuration must be applied on Cisco ACI to avoid a Layer 2 loop?
- A. Apply an MSTP instance on Cisco ACI.
- B. Configure MCP globally
- C. implement BPDU Guard.
- D. Enable STP on downlinks.
Answer: B
NEW QUESTION # 214
Refer to the exhibit.
Refer to the exhibit. A Cisco ACI environment hosts two e-commerce applications. The default contract from a common tenant between different application tiers is used, and the applications work as expected. The customer wants to move to more specific contracts to prevent unwanted traffic between EPGs. A network administrator creates the app-to-db contract to meet this objective for the application and database tiers. The application EPGs must communicate only with their respective database EPGs. How should this contract be configured to meet this requirement?
- A. Implement the app-to-db scope as VRF.
- B. Set the app-to-db scope to Global.
- C. Set the app-to-db scope to Application Profile.
- D. Implement the app-to-db as a Taboo contract.
Answer: C
Explanation:
To ensure that application EPGs communicate only with their respective database EPGs, the app-to-db contract should be configured with a scope set to the Application Profile. This scope ensures that the contract is applied only within the specific application profile, allowing for granular control over the communication between the application and database tiers. By setting the scope to Application Profile, the contract will not apply to other application profiles, thus preventing unwanted traffic between EPGs of different applications1.
Reference:
Cisco ACI Contract Guide White Paper1
NEW QUESTION # 215
Refer to the exhibit. A customer is running an application that collects data from multiple servers.
The application does not support acknowledgments back to the servers. The customer environment is approaching its TCAM limits. The customer must implement a contract that will allow this communication and limit the number of TCAM entries. Which configuration meets these requirements?
- A. Contract CTR-4:
Consumer: EPG-2, EPG-3
Provider: EPG-1
Subject:
Apply Both Direction: enabled
Reverse Filter Ports: enabled
Protocol: UDP, Src Port: Any, Dst Port: 5000 - B. Contract CTR-3:
Consumer: EPG-1
Provider: EPG-2, EPG-3
Subject:
Apply Both Direction: enabled
Reverse Filter Ports: enabled
Protocol: UDP, Src Port: Any, Dst Port: 5000 - C. Contract CTR-2:
Consumer: EPG-1
Provider: EPG-2, EPG-3
Subject:
Apply Both Direction: disabled
Reverse Filter Ports: disabled
Filter from Consumer to Provider:
Protocol: UDP, Src Port: Any, Dst Port: 5000
Filter from Provider to Consumer: empty - D. Contract CTR-1:
Consumer: EPG-2, EPG-3
Provider: EPG-1
Subject:
Apply Both Direction: disabled
Reverse Filter Ports: disabled
Filter from Consumer to Provider:
Protocol: UDP, Src Port: Any, Dst Port: 5000
Filter from Provider to Consumer: empty
Answer: D
Explanation:
You want a single, unidirectional contract where the servers (EPG-2 & EPG-3) act as consumers and the collecting application (EPG-1) is the provider of UDP port 5000.
Disabling Apply Both Directions and Reverse Filter Ports means no reverse‐path TCAM entries are created (since the app never replies), minimizing TCAM use.
Defining only one filter for Consumer→Provider (UDP any → 5000) and leaving the Provider→Consumer side empty achieves exactly the required traffic flow and TCAM efficiency.
NEW QUESTION # 216
Refer to the exhibit.
An engineer must implement the inter-tenant service graph. Which set of actions must be taken to accomplish this goal?
- A. * Define the contract in the provider tenant and export it to the consumer tenant.
* Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant. - B. * Define the contract in the provider tenant and export it to the provider tenant.
* Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant. - C. * Define the contract in the provider tenant and export it to the provider tenant.
* Define the L4-L7 device, service graph template, and ASA bridge domains in the consumer tenant. - D. * Define the contract in the provider tenant and export it to the consumer tenant.
* Define the L4-L7 device, service graph template, and ASA bridge domains in the provider tenant.
Answer: D
NEW QUESTION # 217
A network engineer is implementing a Layer 3 Out in the Cisco ACI fabric. The data center core switches must connect to a pair of leaf switches and exchange routes via a routing protocol. In addition, the implementation must meet these criteria;
* The external switch interface must use 802.1Q tagging.
* Access to the internet for the ACI fabric must be the L30ut.
* The L30ut must use a routing protocol that has rapid convergence time and low CPU usage.
Which configuration set meets these requirements?
- A. Configure the BGP Protocol policy with the appropriate Autonomous System number. Configure an Interface policy and an External Bridged Domain. Create an External Bridged Network and use the configured VLAN pool. Build the Leaf profile and select the Routed sub-interface with the appropriate VLAN.
- B. Configure the OSPF Protocol policy with an area of 0.
Set up the Routed External Network object and Node Profile and select OSPF. Create the Switch profile and select VPC with the appropriate interfaces. Create the default network and associate it with the Routed Outside object. - C. Implement the IS-IS Protocol policy with the selected Autonomous System number. Create the Routed Outside object and Node Profile and select IS-IS. Configure the Interface profile and select the Routed Interface with the appropriate interfaces. Create the External Network object.
- D. Implement the EIGRP Protocol policy with the selected Autonomous System number. Create Routed Outside object and Node Profile and select EIGRP as the routing protocol. Build the Interface profile and select SVI and the appropriate VPC. Configure the External Network object with a network of 0.0.0.070.
Answer: D
NEW QUESTION # 218
Refer to the exhibit.
Refer to the exhibit. A company decided to decrease its routing footprint and remove RT-2 and RT-3 devices from its data center. Because of that, the exit point must be created from all the tenants by using the common tenant. Which two configuration tasks must be completed to meet these requirements? (Choose two.)
- A. Update the L3Out ExtEPG subnet in the common tenant with flag Shared Route Control Subnet and Aggregate Shared Routes.
- B. Move subnets from all the bridge domains to the EPG level and mark them with flag Shared between VRFs.
- C. Export contract Ctr-2 into the tenant TN-1 and attach it as a consumer to all the EPGs in the tenant TN-1.
- D. Mark all subnets with flag Shared between VRFs and attach contract Ctr-3 as a provider to all the EPGs.
- E. Change contract Ctr-3 scope to Global, consume it by all EPGs, and flag all subnets with flag Shared between VRFs.
Answer: A,E
Explanation:
To create an exit point from all tenants using the common tenant and decrease the routing footprint, the following configuration tasks must be completed:
Update the L3Out ExtEPG subnet in the common tenant with flag Shared Route Control Subnet and Aggregate Shared Routes: This configuration allows the subnets to be shared across different VRFs within the common tenant, enabling communication between EPGs that are in different tenants1.
Change contract Ctr-3 scope to Global, consume it by all EPGs, and flag all subnets with flag Shared between VRFs: By changing the scope of contract Ctr-3 to Global, it can be consumed by all EPGs across the fabric. Additionally, flagging all subnets with Shared between VRFs ensures that the subnets can be used by multiple tenants1.
Reference:
Cisco Community Discussion on Common Tenant1
Cisco ACI Basic Configuration Guide2
Cisco ACI Configuring Shared L3Outs Documentation
NEW QUESTION # 219
When Cisco ACI connects to an outside Layers 2 network, where does the ACI fabric flood the STP BPDU frame?
- A. between all the spine and leaf switches
- B. within the APIC
- C. within the bridge domain
- D. within the access encap VLAN
Answer: C
Explanation:
When Cisco ACI connects to an outside Layer 2 network, the ACI fabric floods the STP BPDU frame within the bridge domain (Option A)5. This ensures that BPDUs are properly propagated within the relevant VLAN encapsulation associated with the bridge domain5.
NEW QUESTION # 220
An engineer must limit management access to me Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?
- A. ACL on the management interface of the APIC
- B. policy on the management VLAN
- C. policy In the management tenant
- D. ACL on the console interface
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_0111.html
NEW QUESTION # 221
A customer must upgrade the Cisco ACI fabric to use a feature from the new code release. However, there is no direct path from the current release to the desired one. Based on the Cisco APIC Upgrade/Downgrade Support Matrix, the administrator must go through one intermediate release.
Which set of steps must be taken to upgrade the fabric to the new release?
- A. Upgrade the APICs directly to the targeted release.
Upgrade the switches to an interim release.
When all switches are operational, upgrade the leaf switches to the targeted release.
Upgrade the spine switches to the targeted release. - B. Upgrade the APICs to an interim release and then switches to an interim release.
When all switches are operational, upgrade leaf switches to the targeted release.
Upgrade the spine switches to the targeted release.
Upgrade the APICs to the targeted release. - C. Upgrade the APICs to an interim release.
Upgrade the leaf switches directly to the targeted release.
Upgrade the spine switches directly to the targeted release.
Upgrade the APICs to the targeted release. - D. Upgrade the APICs to an interim release.
Upgrade the switches to an interim release.
Upgrade the APICs to the targeted release.
Upgrade the leaf and spine switches to the targeted release.
Answer: D
NEW QUESTION # 222
An engineer plans to integrate a Cisco ACI fabric with VMware vCenter DVS. Which set of actions must the engineer take to ensure a successful integration?
- A. Set a virtual switch named ACI-VMware-Integration and select Read Write Access mode.
- B. Set a vCenter controller named ACI-VMware-Integration and select Read Write Access mode.
- C. Set a virtual switch named ACI-VMware-Integration and select Read Only Access mode.
- D. Set a vCenter controller named ACI-VMware-Integration and select Read Only Access mode.
Answer: B
NEW QUESTION # 223
......
Earning the Cisco 300-620 certification is essential for IT professionals who work in data center environments and want to enhance their skills and knowledge of Cisco ACI. It is also beneficial for network engineers, architects, and administrators who want to advance their careers and demonstrate their expertise in this field. Passing 300-620 exam is a significant achievement that can open up new career opportunities and increase earning potential.
Cisco 300-620 certification exam is an excellent way for IT professionals to demonstrate their knowledge and expertise in implementing Cisco Application Centric Infrastructure. Implementing Cisco Application Centric Infrastructure certification is highly valued by employers, and those who pass the exam can expect to see career advancement opportunities. With the right preparation and experience, candidates can confidently take the exam and earn their certification.
True 300-620 Exam Extraordinary Practice For the Exam: https://learningtree.testkingfree.com/Cisco/300-620-practice-exam-dumps.html